Built-in steps

Every step kind the harness ships, with its declared schema. Inputs are checked against the schema before the step runs; outputs, after.

Named types:

NameBaseDescription
k8s.Clusterstringa resolved cluster target naming how the run authenticates, never a credential
oci.Artifactstringthe digest of an artifact attached to an image — an SBOM, a signature
oci.Digeststringan OCI content digest (sha256:…), so a reference to content stays one
oci.Refstringan image reference pinned to a digest, as <repository>@<digest>
oci.Tagstringa mutable image reference, as <repository>:<tag>

gsc.sitemap_submit (v1.0.0)

Submits a sitemap to Google Search Console so indexing starts as soon as the domain is verified.

Inputs:

NameTypeDefaultDescription
credentialsstring-the Google service-account JSON key used to authenticate; it is never logged, returned or named in an error
sitestring-the Search Console site identifier, e.g. sc-domain:example.com
sitemapstring-absolute https URL of the sitemap, e.g. https://example.com/sitemap.xml

Outputs:

NameTypeDescription
sitestringthe site submitted for
sitemapstringthe sitemap that was submitted
submittedboolalways true when the step returns

k8s.rollout (v1.1.0)

Applies manifests to a cluster with every image pinned by digest, and waits for the workloads to become healthy.

Inputs:

NameTypeDefaultDescription
tostring-the cluster to deploy to: the environment's name
manifestspath-a manifest file or a directory
imagestring``one repository@sha256:… for every container running that repository
imagesmap{}digest-pinned images by container name, for a manifest with several images
namespacestring``the namespace to deploy into
waitlist[healthy, 5m]the state to wait for and how long, as healthy, 5m
rollbackstringautoauto to roll back a rollout that does not settle, none to leave it
verifystring``the identity every image above must be signed by, as signed-by <identity>: signed-by key:release-key, or signed-by https://token.actions.githubusercontent.com from https://github.com/acme/api/.github/workflows/release.yml@refs/heads/main. An empty value verifies nothing

Outputs:

NameTypeDescription

oci.artifact (v1.0.0)

Push files as an OCI artifact with an artifactType and media types.

Inputs:

NameTypeDefaultDescription
fileslist-the files to package as artifact layers
typestring-artifact type: helm, spdx, cyclonedx, or a verbatim media type
pushoci.Tag-where to push, e.g. registry.example/charts/app:1.0.0
subjectoci.Digest``the image digest this artifact describes, if any (empty for none)
signboolfalsesign the pushed manifest digest

Outputs:

NameTypeDescription
digestoci.Digestthe manifest digest the registry reported
refoci.Refthe repository@digest reference (by digest, never a tag)

oci.image (v1.0.0)

Builds a container image from a Dockerfile, pushes it, and reports the digest the registry confirms.

Inputs:

NameTypeDefaultDescription
frompath-the Dockerfile to build
contextpath-the build context directory; defaults to the Dockerfile's own directory
argsmap{}build args, as ARGs
secretsmap{}secret values by mount name, mounted into the build and never passed as args
platformslist[]platforms to build for; more than one produces an image index. Empty means the platform the build runs on
targetstring``the stage to build
pushoci.Tag-the image reference to push
signboolfalsewhether to sign the image
sbomboolfalsewhether to ask for an SBOM alongside the image
cachestringlocalwhere the builder may keep its cache: registry, local or none

Outputs:

NameTypeDescription
digestoci.Digestthe digest the registry holds
refoci.Refthe image pinned to that digest, as <repository>@<digest>
tagoci.Tagthe reference that was pushed
signedboolwhether it was signed
sbomoci.Artifactthe SBOM artifact's digest, or empty when there is none
provenanceoci.Artifactthe attached SLSA provenance envelope's digest, or empty when there is none
platformslistthe platforms the image was built for

oci.verify (v1.0.0)

Refuses to continue unless an image digest carries a signature from a named identity.

Inputs:

NameTypeDefaultDescription
imagestring-the digest-pinned image to verify, as repository@sha256:…
signed_bystring-who must have signed it: key:<key-id>, or <subject> from <issuer>

Outputs:

NameTypeDescription
digeststringthe verified digest
identitystringthe identity the signature was made as

tofu.apply (v1.0.0)

Applies exactly the plan file an approval was bound to, refusing if its sha256 no longer matches.

Inputs:

NameTypeDefaultDescription
planmap-the tofu.PlanFile tofu.plan emitted as file: {path, sha256, dir}, with sha256 the digest the approval was bound to

Outputs:

NameTypeDescription
outmapthe root module's non-sensitive outputs, by name; sensitive ones are counted in the log, never returned
appliednumberhow many resources the apply changed (created, updated and destroyed)

tofu.plan (v1.0.0)

Plans an infrastructure directory, and reports what it would change.

Inputs:

NameTypeDefaultDescription
dirpath-the directory to plan
backendstringlocalthe backend kind
backend_configmap{}backend settings for tofu init
varsmap{}the input variables the plan is made with

Outputs:

NameTypeDescription
filemapthe saved plan as { path, sha256 }
changesmapthe plan's resources, and the three counts
addsinthow many it creates, replacements included
changes_countinthow many it updates in place
destroysinthow many it destroys, replacements included
emptyboolwhether it changes nothing
summarystringthe plan in plain terms

vm.deploy (v1.1.0)

Deploys to a fleet of hosts over SSH, one batch at a time, and reports how many came up.

Inputs:

NameTypeDefaultDescription
hostslist-the fleet: address and host_key are required on every entry, and a host with no pinned host_key is refused rather than trusted on first use. Each entry also takes port (22), user (ssh_user), and host_key_algorithm (ssh-ed25519)
batchstring1how many hosts per batch: a count, or a percent of the fleet such as "25%". A percent rounds up and is never zero
runlist-commands to run on each host as it is deployed, in order, as { program, args, timeout }. The argv is typed, never a shell string
healthstring-a probe command to run on each host after its commands; the deploy waits for it to report healthy. Without one there is no health gate
health_timeoutint60how long the health gate polls a host before calling it failed
max_failuresint0how many hosts may fail health before the deploy stops and rolls back
rollbacklist-commands that restore a host's previous artifact, in the same { program, args, timeout } shape as run, run on every host of a failed batch
ssh_userstringdeploythe user to deploy as, for the hosts that do not name one
imagestring-the digest-pinned artifact the deploy ships, as repository@sha256:…; verification checks the signature on this digest
verifystring``the identity image must be signed by, as signed-by <identity>: signed-by key:release-key, or signed-by https://token.actions.githubusercontent.com from https://github.com/acme/api/.github/workflows/release.yml@refs/heads/main. An empty value verifies nothing

Outputs:

NameTypeDescription
healthyintthe hosts that reached health
totalintthe hosts in the fleet
summarystringthe fleet in one line, as {healthy}/{total} hosts healthy